Who we are
CrewFlow is tour and crew management software operated by:
CrewFlow v/ Stian Nafstad
Selma Ellefsens Vei 3M
0581 Oslo
Norway
Privacy enquiries: privacy@crewflow.io
Who controls your data
This matters more in CrewFlow than in most products, because most data here is put in by somebody other than the person it describes.
- For your own account — your name, address, profile, sign-in methods — we are the controller.
- For tour data — schedules, travel, accommodation, assignments, documents, guest lists — the organization that created the tour is the controller, and we process it on their behalf. If your employer or tour manager invited you to CrewFlow, questions about why they hold something, or requests to have it changed, go to them first. We will help, but we cannot overrule the organization's own record-keeping.
- For emergency contacts, whoever entered the details is responsible for having told that person. See the section below.
What we hold
Account and identity
Email address, first and last name. The sign-in providers you link (Google, Apple, email link, password) and the identifiers they give us. Verified email addresses and the challenges used to prove ownership when linking a second sign-in method. Failed sign-in attempts and lockout timestamps, kept to stop brute-force attacks. A personal calendar-feed token.
Profile
Phone number and country code, biography, profile picture, timezone.
Emergency contact
Name, phone number and relationship of a person you nominate. This is personal data about somebody who is usually not a CrewFlow user and has not agreed to anything with us. We hold it only so it is reachable in an emergency on a show day. See Emergency contacts below.
Tour and operational data
Tours, shows, venues and schedules, and which crew are assigned to them. Travel itineraries including flights, transport legs, booking references and layovers. Accommodation including hotels, addresses and check-in and check-out dates. Crew check-in and check-out times. Messages you write in an event. Guest lists, including the names of guests you add who are not users. Documents you upload — contracts, riders, itineraries — and a log of who accessed them.
Device and technical
Push notification tokens and the platform they belong to. Your IP address and browser or app user agent, recorded in audit logs, document access logs and consent records. Crash and error reports.
Commercial
Stripe customer and subscription identifiers. Card details are held by Stripe and never reach CrewFlow.
Why we hold it, and on what basis
- Account and identity — to let you sign in and to keep the account yours. Basis: performance of a contract.
- Profile — so crew on a tour can identify and reach each other. Basis: legitimate interests.
- Emergency contact — so somebody can be reached if you are hurt or missing on a show day. Basis: vital interests, and the legitimate interests of the organization.
- Tour and operational data — to run the tour the organization invited you to. Basis: performance of a contract, and the organization's legitimate interests.
- Failed sign-ins, audit logs, document access logs — to detect and investigate unauthorised access. Basis: legitimate interests, and our legal obligation to keep the service secure.
- Push tokens — to send you the schedule changes you asked for. Basis: consent, withdrawable at any time in notification settings.
- Crash and error reports — to find and fix faults. Basis: legitimate interests.
- Stripe identifiers — to take payment and manage a subscription. Basis: performance of a contract.
Emergency contacts
If you entered somebody as your emergency contact, you are responsible for telling them that their name, phone number and relationship to you are stored in CrewFlow and visible to the managers of tours you are on. We do not contact them to say so.
If you are an emergency contact and want your details removed, ask the person who entered them, or write to us and we will remove them.
Who we share it with
We do not sell personal data. We use these processors:
- Google (Firebase) — authentication. EU / US.
- Heroku (Salesforce) — hosting and database. EU (Ireland).
- Cloudflare (R2) — uploaded files. EU.
- Stripe — payments. EU / US.
- SendGrid (Twilio) — email. EU / US.
- Sentry — crash and error reports. EU (Germany).
- Mapbox — maps and geocoding. US.
- Google Maps — traffic estimates. EU / US.
- Apple (APNs) and Google (FCM) — push notifications. EU / US.
Flight status lookups send only a flight number and a date to the flight data provider, never your name or booking reference.
Tour data is also visible to the other members and managers of the tours you belong to. That is the point of the product, but it is worth saying plainly: a tour manager can see your profile, your assignments, your travel and your emergency contact.
Transfers outside the EEA
Several processors above are US-based. Google, Salesforce (Heroku), Cloudflare, Stripe, Twilio (SendGrid), Functional Software (Sentry) and Mapbox are certified under the EU–US Data Privacy Framework, and those transfers rely on the European Commission's adequacy decision for it. Transfers to Apple rely on the European Commission's Standard Contractual Clauses. Where a certification lapses, the Standard Contractual Clauses apply instead.
How long we keep it
Until you or your organization delete it. CrewFlow has no automatic deletion or retention schedule today. Tours from years ago, and the travel and assignment records attached to them, remain until somebody removes them.
We would rather say that than publish a retention table the system does not implement. If we introduce automatic retention periods, we will update this policy and tell you before they take effect.
Deleting your account
You can delete your account from the app or the portal. When you do:
- Your account, profile, emergency contact, sign-in methods and push tokens are deleted.
- Your tour history goes with it. Crew assignments and the messages you wrote are removed along with the account. Tours you worked on will no longer show that you were there. This is not recoverable.
- Records we must keep to run the service or meet a legal obligation — billing records, security audit logs, and the record that you accepted a given version of this policy (kept without your name or address) — are retained for as long as that obligation lasts.
If you are the last owner of an organization, contact us before deleting: the organization's tours and the data of everyone on them are involved, and that needs handling deliberately rather than as a side effect.
Your rights
Under the GDPR you can ask for access, correction, deletion, restriction, portability, and to object to processing based on legitimate interests. You can also withdraw consent where we rely on it, and complain to a supervisory authority — in Norway, Datatilsynet.
In practice today:
- Access and portability — the app and portal can export your data.
- Correction — edit your profile directly; for tour data, ask the organization that entered it.
- Deletion — delete your account as above.
- Restriction and objection — these are not yet built as self-service. Write to privacy@crewflow.io and we will handle the request by hand.
We answer within one month.
Security
Transport is encrypted. Passwords are handled by Firebase, not by us. Authorization is enforced on the server for every request, and access to another organization's or tour's data is refused rather than hidden in the interface. Document access is logged. Crash reports are scrubbed of credentials and personal data before they leave your device or our servers.
No system is perfectly secure, and we do not claim otherwise.
Children
CrewFlow is for professional touring work and is not intended for anyone under 16. We do not knowingly collect their data.
Changes
If we change this policy materially we will tell you in the app or by email before the change takes effect. The version and date are at the top.
Website & waitlist
The policy above covers the CrewFlow app and portal. This section covers crewflow.io, the marketing site you are reading now.
What the website collects
If you join the waitlist we store the name and email address you enter, the fact that you ticked the consent box, and when. The consent box is unticked by default and the form does not submit without it.
We use TelemetryDeck for anonymised, cookieless usage analytics. It sets no cookies and does not identify you. See telemetrydeck.com/privacy.
Waitlist mail is sent through SendGrid (Twilio), which may record whether a message was opened or a link clicked. Every message carries an unsubscribe link and our postal address; unsubscribing removes you from the list and tells SendGrid not to mail you again. See twilio.com/legal/privacy.
Your rights and contact
To access, correct or delete what the website holds about you, or to withdraw consent, write to privacy@crewflow.io. To delete a CrewFlow app account, see Delete your account.
Privacy: privacy@crewflow.io
Support: support@crewflow.io
Address:CrewFlow v/ Stian Nafstad
Selma Ellefsens Vei 3M
0581 Oslo
Norway